Security and Compliance FAQ
Answers to common questions about Enrich Layer's security practices, certifications, data storage, retention, and access controls.
This page answers the security and compliance questions we most often receive during procurement, vendor assessments, and due diligence.
Certifications and audits
Do you hold SOC 2 Type II, ISO 27001, or PCI certifications?
We do not currently hold formal certifications. However, we follow the control objectives defined in SOC 2 and ISO 27001, and our team will complete any security or due-diligence questionnaire your organization provides.
Can you provide third-party penetration test results?
We have not commissioned a third-party penetration test to date. We're happy to provide detailed answers to your security questionnaire — contact our support team to get started.
Do you offer a Data Processing Agreement (DPA)?
Yes. Our DPA covers our GDPR obligations, including Article 28 processor terms. Contact our support team to request a copy.
Are you registered as a California data broker?
Yes. Enrich Layer is registered as a California data broker.
Data usage and storage
What are you permitted to do with data we provide?
We store only the fields needed to deliver API responses, monitor performance, and investigate support issues. We never sell your data or share it with third parties for their own purposes.
What data do you collect from our usage?
We collect and maintain usage logs, including queries, response times, and other technical details. We use these operationally for billing, monitoring service health, and improving reliability — not to build or train separate products from your data.
Where is customer data stored?
Customer data is stored in datacenters located in the United States.
Is customer data separated from other customers' data?
Data resides in a multi-tenant database. Each tenant has a dedicated schema, providing strict logical isolation. Storage is not physically separate.
Data retention and access
How long is data kept, and how is it deleted?
Usage logs are rotated and automatically pruned, typically after 3–6 months.
Who at Enrich Layer can access our data?
Access is limited to employees and vetted contractors who need it for support or engineering work. All access is time-bound, logged, and reviewed.